No Image

USN-6301-1: Linux kernel vulnerabilities

2023-08-18 KENNETH 0

USN-6301-1: Linux kernel vulnerabilities It was discovered that the netlink implementation in the Linux kernel did not properly validate policies when parsing attributes in some situations. An attacker could use this to cause a denial of service (infinite recursion). (CVE-2020-36691) Billy Jheng Bing Jhong discovered that the CIFS network file system implementation in the Linux kernel did not properly validate arguments to ioctl() in some situations. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-0168) It was discovered that the ext4 file system implementation in the Linux kernel contained a use-after-free vulnerability. An attacker could use this to construct a malicious ext4 file system image that, when mounted, could cause a denial of service (system crash). (CVE-2022-1184) It was discovered that some AMD x86-64 processors with SMT enabled could speculatively execute instructions using [ more… ]

No Image

Update to Windows Subsystem for Android™ on Windows 11 (August 2023)

2023-08-18 KENNETH 0

Update to Windows Subsystem for Android™ on Windows 11 (August 2023) We’ve shipped an update for Windows Subsystem for Android™ on Windows 11 to all Windows Insider channels. This update (2307.40000.5.0) includes improvements to system and graphics reliability.  What’s New  Platform stability improvements. Updated latest Chromium WebView to version 115. Android 13 security updates. Giving feedback  If you are having issues with Windows Subsystem for Android™ – please file feedback via Feedback Hub under Apps > Windows Subsystem for Android™. For more information about troubleshooting and submitting feedback: Troubleshooting and FAQ for mobile apps on Windows. If you’re a developer, please give feedback at our Github site.  Thanks, Windows Subsystem for Android™ Team  Source: Update to Windows Subsystem for Android™ on Windows 11 (August 2023)

No Image

USN-6300-1: Linux kernel vulnerabilities

2023-08-18 KENNETH 0

USN-6300-1: Linux kernel vulnerabilities William Zhao discovered that the Traffic Control (TC) subsystem in the Linux kernel did not properly handle network packet retransmission in certain situations. A local attacker could use this to cause a denial of service (kernel deadlock). (CVE-2022-4269) It was discovered that the NTFS file system implementation in the Linux kernel did not properly check buffer indexes in certain situations, leading to an out-of-bounds read vulnerability. A local attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2022-48502) Seth Jenkins discovered that the CPU data to memory implementation for x86 processors in the Linux kernel did not properly perform address randomization. A local attacker could use this to expose sensitive information (kernel memory) or in conjunction with another kernel vulnerability. (CVE-2023-0597) It was discovered that a race condition existed in the btrfs file system [ more… ]

No Image

USN-6299-1: poppler vulnerabilities

2023-08-18 KENNETH 0

USN-6299-1: poppler vulnerabilities It was discovered that poppler incorrectly handled certain malformed PDF files. If a user or an automated system were tricked into opening a specially crafted PDF file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2020-36023, CVE-2020-36024) Source: USN-6299-1: poppler vulnerabilities

No Image

Amazon EC2 M7a 범용 인스턴스 출시 – 4세대 AMD EPYC 프로세서 탑재

2023-08-18 KENNETH 0

Amazon EC2 M7a 범용 인스턴스 출시 – 4세대 AMD EPYC 프로세서 탑재 2021년 11월, 최대 3.6GHz의 주파수에서 실행되는 3세대 AMD EPYC(Milan) 프로세서로 구동되는 Amazon EC2 M6a 인스턴스를 출시했습니다. 이 인스턴스는 고객에게 M5a 인스턴스에 비해 가격 대비 성능이 최대 35% 향상되었습니다. SAP와 같이 x86 지침에 의존하는 워크로드를 실행하는 많은 고객은 클라우드 활용도를 최적화할 방법을 찾고 있습니다. EC2가 제공하는 컴퓨팅 옵션을 활용하고 있습니다. 오늘, 최대 3.7GHz의 주파수에서 실행되는 4세대 AMD EPYC(Genoa) 프로세서로 구동되는 새로운 범용 Amazon EC2 M7a 인스턴스를 발표합니다. 이 인스턴스는 M6a 인스턴스 대비 최대 50% 향상된 성능을 지원합니다. 이렇게 향상된 성능을 통해 데이터를 더 빠르게 처리하고, 워크로드를 통합하고, 소유 비용을 낮출 수 있습니다. M7a 인스턴스는 AVX-512, 벡터 신경망 명령어(VNNI) 및 bfloat16(brain floating point)을 지원합니다. 이러한 인스턴스에는 인메모리 데이터에 고속 액세스를 가능하게 하는 DDR5(Double Data Rate 5) 메모리가 탑재되어 있으며, 지연 시간을 줄이기 위해 M6a 인스턴스보다 2.25배 향상된 메모리 대역폭을 제공합니다. [ more… ]